Back to Blog
|15 min readOpinion

Who Holds the Other End of Your AI Conversation?

The trust architecture of AI is a structural design flaw, not a privacy policy problem.

By Satish Singh, CEO, Scrutora

Every day, millions of people tell AI things they wouldn’t tell their closest friend.

Their fears. Their business strategies. Their medical symptoms. Their relationship problems. Their financial situations. Their political views. Their insecurities. Their diagnoses. Their legal exposure. Their secrets.

They do this because AI feels safe. It doesn’t judge. It doesn’t gossip. It doesn’t have an agenda. It doesn’t get tired of your questions. It doesn’t tell your spouse what you asked at 2 AM. It just helps.

And so people open up. Completely. In ways they never would with a search engine, a social media platform, or even a therapist.

That openness is the product’s greatest strength. It is also the greatest structural risk in modern technology.

Behind Every Conversation Is a Company

Behind every AI conversation is a company. A company with servers, investors, board members, quarterly targets, and a legal jurisdiction. A company that stores every word you type on infrastructure it controls.

This isn’t a criticism of any specific AI company. Most are led by people who genuinely care about safety and privacy. Anthropic was founded by researchers who left OpenAI because they wanted to prioritize safety. OpenAI started as a nonprofit. Google’s original motto was “Don’t be evil.”

None of this diminishes how useful AI already is. It highlights how important it’s about to become. And that’s exactly why the architecture matters now, before the incentives shift.

History Has a Pattern

Every major communication technology followed the same arc: built for connection, trusted by users, exploited when incentives changed.

Telecom Networks

Built so people could talk to each other. In the 1950s and 60s, AT&T’s infrastructure became the backbone of the NSA’s surveillance programs. Operation SHAMROCK collected every international telegram entering or leaving the US for over 30 years. The infrastructure built for conversation became an infrastructure for monitoring. No new technology was needed. The phone lines were already there.

Email

Built for fast, private communication. Gmail launched in 2004 with a revolutionary promise: free, massive storage. The cost was invisible. Google scanned every email to serve targeted ads. The content of your private messages (your flight confirmations, your medical appointment reminders, your arguments with your partner) all fed an advertising engine. They stopped scanning for ads in 2017. They still process emails for other features.

Social Media

Built to connect friends. Facebook’s social graph, the map of who knows whom and what they care about, became Cambridge Analytica’s targeting weapon in 2016. 87 million user profiles were harvested not through a hack but through a feature. A personality quiz. Users volunteered the data. The platform’s architecture made the exploitation possible. The founders didn’t plan for it. The architecture allowed it.

Search Engines

Built to organize information. Google’s search data became the most valuable behavioral dataset in history. What you search for reveals what you fear, what you want, what you’re hiding, and what you’ll buy. That data shaped an advertising empire worth over a trillion dollars.

In every case, the pattern was identical: trust was built, data was accumulated, and when the incentives shifted, the infrastructure was already in place for exploitation. No conspiracy was needed. Just a business model and a board meeting.

AI Is Different. Here’s Why.

Every previous technology captured one dimension of human behavior:

  • Telecom captured who you talk to
  • Email captured what you communicate
  • Social media captured what you like and who you know
  • Search captured what you want to know

AI captures something far more intimate: how you think.

When you have a conversation with an AI, you’re not just sharing information. You’re revealing your reasoning process. How you weigh decisions. What makes you anxious. How you respond to pushback. What motivates you. What you’re insecure about. How you process bad news. What kind of language persuades you.

A social media company knows you liked a post about anxiety. An AI company knows you described your specific anxiety symptoms at 2 AM, asked follow-up questions about medication options, and were persuaded by a response that framed the issue as temporary rather than chronic.

That’s not metadata. That’s a psychological profile more detailed than anything a therapist builds over years, generated in a single conversation, stored on a server you don’t control. And unlike a therapist, there’s no professional oath, no licensing board, no legal privilege protecting that conversation.

The Healthcare Angle Nobody Is Talking About

Here’s a concrete example from my work in healthcare security.

When a patient tells their doctor about symptoms, that conversation is protected by HIPAA. The doctor’s office has a Business Associate Agreement with every vendor that touches that data. There are encryption requirements, access controls, audit trails, and breach notification obligations.

When that same patient types the same symptoms into ChatGPT, Claude, or Gemini, none of those protections exist. No BAA. No HIPAA coverage. No encryption mandate for the conversation at rest. No breach notification if the data is compromised. No audit trail of who accessed it.

That patient just created an unprotected health record on a corporate server.

Multiply this by millions of people asking AI about their symptoms, medications, mental health, diagnoses, and treatment options every day. The largest unprotected health dataset in history is being built right now, one conversation at a time, with zero regulatory oversight.

This isn’t theoretical. It’s happening today. And no AI company’s privacy policy changes the structural reality: the data exists, on their servers, under their control.

The Real Risk Isn’t Malice. It’s Architecture.

The most likely exploitation scenario isn’t a dramatic hack or a villainous CEO deciding to sell your data. It’s much more mundane.

Scenario 1: The Acquisition

A well-intentioned AI company gets acquired by a larger company with different values and a different business model. The conversation data comes with the acquisition. The new parent company’s privacy policy applies. The data that was collected under one set of promises is now governed by another.

Scenario 2: The Government Request

A national security letter arrives. The company is legally compelled to provide conversation data for specific users. This already happens with email providers, social media companies, and telecom firms. AI companies are not exempt.

Scenario 3: The Business Model Shift

Revenue growth slows. Investors push for monetization of the data asset. The company introduces “personalized recommendations” or “AI-powered insights” that require mining conversation history. Each step is small. Each step is justified. The end state is unrecognizable from the original promise.

Scenario 4: The Subtle Influence

This is the most dangerous because it’s the hardest to detect. Small adjustments to how the AI frames information, which products it mentions first, how it characterizes political issues, what it emphasizes and what it omits. Not lying. Just nudging. Across millions of conversations. Personalized to each user’s psychological profile. Undetectable at the individual level. Devastating at scale.

None of these require malice. They require only the same incentive structures that transformed every previous communication technology.

What “Separation of Intelligence and Memory” Actually Means

The solution isn’t to stop using AI. It’s too useful and too important for that. The solution is structural.

User-owned conversation data. Your AI conversations should be encrypted with keys only you control, stored on your device or in storage you own. The AI company should process your messages and return responses without retaining the conversation. The model doesn’t need your history to be useful. It needs your current context.

Independent data custodians. If conversation history needs to be stored for product features like memory or personalization, it should be held by independent third parties with no commercial relationship to the AI provider. The same way a bank uses an independent auditor, AI companies should use independent data custodians.

On-device inference. Models that run locally on your hardware, with no server in the middle. This technology exists today but lags behind cloud models in capability. The gap is closing. When it closes, the architecture problem disappears.

Mandatory audit infrastructure. Independent organizations with actual authority to inspect what AI companies do with conversation data. Not self-reported transparency reports. Real audits with subpoena power.

Regulatory separation. Laws that explicitly prevent the entity that builds the model from being the entity that controls the conversation data. We separated commercial banking from investment banking after 1929. We need a similar separation for AI capability and AI memory.

The Window Is Now

Every structural safeguard in history was built after a scandal, not before.

Financial regulation came after the 1929 crash. Privacy regulation came after Cambridge Analytica. Data breach notification laws came after millions of records were stolen. HIPAA came after years of medical records being mishandled.

AI will be exploited eventually. The only question is whether we build the safeguards before that moment or because of it.

We usually choose because of it.

Right now, in 2026, we’re in the window between trust and exploitation. The trust is built. The data is accumulating. The architecture is set. The incentives haven’t shifted yet. But they will. They always do.

The time to fix the architecture is now. While the companies still have good intentions. While the founders still have control. While the conversation data is measured in billions of messages, not trillions.

After the first scandal, it will be too late to redesign the foundation. You can’t un-collect data that’s already stored. You can’t un-train a model that’s already learned your psychology. You can’t un-ring a bell.

The question for everyone using AI today is simple: you trust the company holding your conversations. But do you trust every future owner of that company, every future board member, every future government request, and every future business model pivot? If the answer isn’t an unqualified yes, then the architecture needs to change. Before it’s too late.

This article was written by Satish Singh, Founder and CEO of Scrutora, a healthcare code compliance platform. The views expressed are about the broader AI industry, not any specific company.

Building healthcare software with AI?

Scrutora scans your codebase for compliance gaps across HIPAA, GDPR, SOC 2, and DPDPA, including agentic AI rules that map how patient data flows through AI pipelines.